Skip to content
APEX & Omega Terminal
Terminals Brokers Security FAQ
Compare the two Download
APEX & Omega
Terminals Compare Features Brokers Security Download FAQ
Download free Compare terminals
Back to the home page

Privacy

Last updated: 28 September 2026

There are two separate things to talk about: the software, which runs on your machine, and this website, which serves you the download. They are treated differently and the distinction matters.

1. The software

We receive nothing

APEX Terminal and Omega Terminal have no account system, no sign-up, no licence check, no analytics and no telemetry. Neither application sends any data to COMPANY NAME or to any third party at any time. There is no mechanism in the software by which it could.

The applications run a local server bound to 127.0.0.1 — the loopback address. That address is not reachable from your local network, let alone from the internet. A request arriving with an origin other than loopback is refused outright.

What the software stores, and where

Everything is written to your own disk, under your own Windows user profile:

  • Encrypted credential vault — your broker API keys and tokens, encrypted with AES-256-GCM. The encryption key is stored in a separate file beside the vault, so a copy of the vault alone cannot be read.
  • Desk state — watchlists, alerts, risk limits, auto square-off rules, charges configuration, baskets and paper-trading books.
  • Window layout and preferences — including your keyboard map, stored in the browser-engine local storage belonging to the application.
  • Strategies and journal (APEX only) — strategy definitions, run records and an append-only per-day journal of every entry, exit, target and stop.

These live in %APPDATA%\APEX Terminal and %APPDATA%\Omega Terminal respectively. To remove everything, delete those folders.

One-time authentication codes are never stored

A TOTP code you type at connect time is used once and discarded; it is dead within thirty seconds anyway. Only a static TOTP setup key can be saved, only if you choose to save it, and only encrypted. Anything resembling a secret, token, password, PIN or key is masked before it is written to any log.

Your broker does see your traffic

The software connects directly to your broker's REST and WebSocket endpoints using your own API credentials. Your broker therefore sees your orders, your market data subscriptions and your account activity, exactly as they would if you used the broker's own application. Their privacy policy governs that relationship, not ours.

2. This website

No cookies, no tracking scripts

This site sets no cookies of any kind and runs no analytics, advertising or session-recording script. Nothing in the page identifies you, follows you between visits, or is passed to an advertising network. There is no sign-up, no account and no newsletter.

What is recorded when you visit

Two parties see your request: the server this site runs on, and Cloudflare, which sits in front of it.

Our access log. The web server writes one line per request. That line contains your IP address and the country Cloudflare resolved it to, the date and time, the page or file you asked for, the HTTP status returned, the size of the response and how long it took to serve, your browser’s user-agent string, and — when your browser chooses to send one — the page you arrived from.

That log exists to count traffic and to diagnose faults. It is not used to build a profile of you, is never combined with any other source, and is never sold, rented or shared. Log files are kept for 30 days and are then deleted automatically.

Cloudflare, Inc. terminates the HTTPS connection, serves cached files from a location near you, and filters abusive traffic. Operating that network necessarily means processing your IP address and the metadata of your request. Cloudflare also compiles aggregate traffic statistics for us — visit counts, countries, bandwidth, which files were requested — which we can see in their dashboard and which do not identify individual visitors. Cloudflare acts as our processor under its own terms; see the Cloudflare Privacy Policy.

Fonts are loaded from Google

Two of the typefaces used here are served by Google Fonts, so your browser fetches them from fonts.googleapis.com and fonts.gstatic.com. Google therefore receives your IP address and user-agent when the page loads. Google states that these requests are not used to create profiles or to serve advertising; see the Google Fonts privacy notice. Every other file on this site — the stylesheet, the scripts, the images, the background videos and the installers — is served from this domain. No other third party receives anything.

Downloads

Downloading an application requires no email address, no registration and no identifying information of any kind. It is an ordinary HTTPS file transfer, and it appears in the access log described above exactly like any other request.

3. Your rights

We hold no accounts, no profiles and no contact details, so in almost every case there is nothing for us to export, correct or delete on your behalf. The one exception is the 30-day server access log described above, which contains IP addresses.

To exercise a right of access or erasure over that log, write to privacy@yourdomain.com with the IP address you visited from and the approximate date and time — without those we have no way to find your entries, because nothing in the log is linked to a name. If the entries are still within the 30-day window we will locate and remove them; after that they are already gone.

4. Changes

If this policy changes, the "last updated" date above changes with it. Material changes will be noted on the home page.

5. Contact

COMPANY NAME, registered address. Email privacy@yourdomain.com.

Risk disclaimer  ·  Terms of use

APEX & Omega Terminal Home Risk disclaimer Terms of use Privacy © 2026 APEX & Omega Terminal. All rights reserved.